Sign in

William • SOC and Detection Engineering

@williamincyber.bsky.social
59 followers 58 following 1K posts

ISC2 CC | Building toward Tier 1 SOC and Detection Engineering | Hands-on investigations with Splunk, Wazuh and Sigma | Documenting what I learn

PostsRepliesMedia
William • SOC and Detection Engineering @williamincyber.bsky.social · 55m
Not everything dangerous is a vulnerability. A vulnerability is a weakness. A threat is something that could cause harm by exploiting or affecting what you value. Knowing the weakness matters. Knowing what could act against it gives the risk context.
000
William • SOC and Detection Engineering @williamincyber.bsky.social · 1h
Buying the hardware was easy. Deciding what job it should have is where the real lab starts. Part 2 of rebuilding my SOC home lab. This is the Ubiquiti UniFi Cloud Gateway Ultra. Its job: become the network control layer behind my new environment.
110
William • SOC and Detection Engineering @williamincyber.bsky.social · 2h
Cyber Awareness Day 2 I used to start labs by generating suspicious activity. Now I start with the baseline. What normally happens? What telemetry should appear? What should stay silent? Before I call something abnormal, I need to understand what normal looks like.
000
William • SOC and Detection Engineering @williamincyber.bsky.social · 2h
An attacker needs a way in. That path is called an attack vector. It could be a phishing email, stolen credentials, an exposed service or a vulnerable application. The attack is what happens. The attack vector is how the attacker gets the opportunity.
000
William • SOC and Detection Engineering @williamincyber.bsky.social · 8h
Cyberattacks do not happen by themselves. Someone is behind the activity. That is a threat actor. It can be an individual or group capable of carrying out malicious cyber activity. Understanding what happened matters. Understanding who might benefit can add context.
010
William • SOC and Detection Engineering @williamincyber.bsky.social · 9h
I thought I had a Splunk problem. I actually had a visibility problem. That distinction changed how I troubleshoot my SOC home lab. Because a working SIEM search depends on much more than SPL.
110
William • SOC and Detection Engineering @williamincyber.bsky.social · 10h
It’s 1:26 AM. I told myself I’m solving 100 Security+ questions before I sleep tonight. 80 done. 20 to go. Some nights the motivation is there. Other nights it’s just commitment. Tonight, it’s commitment. Back to the questions.
010
Reposted by William • SOC and Detection Engineering
William • SOC and Detection Engineering @williamincyber.bsky.social · 27/07/2026
I put together a complete CCNA in 8 Weeks roadmap and decided to make it free for everyone. If you're preparing for the CCNA or want to become a Junior Network Engineer, this guide gives you a structured path instead of guessing what to study next. 🧵
212
William • SOC and Detection Engineering @williamincyber.bsky.social · 11h
Your website can be online and still need a security guard. That is where a WAF comes in. A Web Application Firewall inspects web traffic and can block requests that match malicious patterns. The server stays reachable. Suspicious requests get challenged or blocked.
010
William • SOC and Detection Engineering @williamincyber.bsky.social · 13h
Your laptop can tell a story about what happened during an attack. EDR helps defenders read it. Endpoint Detection and Response monitors endpoint activity to help detect, investigate and respond to threats. The endpoint is not just a device. It is evidence.
010
William • SOC and Detection Engineering @williamincyber.bsky.social · 14h
I’m retiring the SOC home lab that taught me almost everything I know so far. Not because it stopped working. Because I’ve outgrown the way I built it. Splunk. Wazuh. Sysmon. Windows. Linux. Most of it lived around my Mac. Now I’m rebuilding from the infrastructure up.
110
William • SOC and Detection Engineering @williamincyber.bsky.social · 16h
Attackers leave patterns behind. Threat intelligence turns those patterns into knowledge defenders can use. It provides context about threats, tactics and indicators to support security decisions. Good intelligence does more than inform. It helps you know what to look for.
010
William • SOC and Detection Engineering @williamincyber.bsky.social · 17h
I have 3 weeks to pilot a cybersecurity product. I’m choosing to use 7 focused days. And I’m not testing anything yet. Generating a result is easy. I want to understand why I got it. So this pilot starts with theory, not the tool.
110
William • SOC and Detection Engineering @williamincyber.bsky.social · 18h
What if you could find the weakness before an attacker does? That is penetration testing. It is an authorized attempt to find and validate security weaknesses by simulating attacks. The goal is simple: Find it. Prove it. Fix it.
010
William • SOC and Detection Engineering @williamincyber.bsky.social · 20h
A vulnerability is discovered. Does that mean the software stays vulnerable forever? Not necessarily. A patch is an update designed to fix bugs or security weaknesses. Finding vulnerabilities matters. Applying the fix matters too.
010
William • SOC and Detection Engineering @williamincyber.bsky.social · 01/10/2026
Cyber Awareness Day 1 An alert is not a conclusion. A detection tells me something matched. It does not automatically prove malicious activity. The alert gets my attention. The evidence determines what happens next.
010
William • SOC and Detection Engineering @williamincyber.bsky.social · 30/09/2026
Getting into a system is not always the final goal. The payload is what performs the intended action after delivery or execution. It might steal data, encrypt files or run malicious code. Think of it simply: Delivery gets it there. The payload does the work.
110
William • SOC and Detection Engineering @williamincyber.bsky.social · 30/09/2026
The fastest way to make everything in a SOC lab look suspicious? Never learn what normal looks like first. That’s the first change I’m making in my home lab. Before generating suspicious authentication activity, I’m establishing the baseline.
100
William • SOC and Detection Engineering @williamincyber.bsky.social · 30/09/2026
If you have a Windows VM, you already have enough to build this SOC project. 𝗠𝗮𝗹𝗶𝗰𝗶𝗼𝘂𝘀 𝗣𝗼𝘄𝗲𝗿𝗦𝗵𝗲𝗹𝗹 𝗜𝗻𝘃𝗲𝘀𝘁𝗶𝗴𝗮𝘁𝗶𝗼𝗻 Enable PowerShell logging. Generate a few safe commands yourself. Then investigate the evidence they leave behind.
110
William • SOC and Detection Engineering @williamincyber.bsky.social · 30/09/2026
I changed how I start cybersecurity projects. I used to jump straight into the technical work. Now I prepare the investigation first. Objective. Scope. Baseline. Expected telemetry. Evidence storage. Investigation journal. The work starts before the first command.
100
William • SOC and Detection Engineering @williamincyber.bsky.social · 30/09/2026
I made one of my first home lab mistakes before the lab was even running. I didn’t check my system architecture. I was excited to start building, so I went straight to downloading what I needed. That small assumption created a problem I could have avoided.
100
William • SOC and Detection Engineering @williamincyber.bsky.social · 30/09/2026
I cannot recreate production SOC experience at home. But I can deliberately create the investigation repetitions that build stronger analyst habits. That realization is changing how I use my home lab.
110
William • SOC and Detection Engineering @williamincyber.bsky.social · 29/09/2026
I thought building a SOC home lab was about learning more tools. I’m starting to realize that’s not the real advantage. The real advantage is repetition. Seeing the same telemetry under different situations until I start recognizing the pattern.
110
William • SOC and Detection Engineering @williamincyber.bsky.social · 29/09/2026
The most dangerous software might be the one you never notice. That is spyware. It secretly monitors activity or collects information from a device without the user knowing. Passwords. Browsing activity. Personal data. Sometimes the goal is not disruption. It is observation.
000
William • SOC and Detection Engineering @williamincyber.bsky.social · 29/09/2026
Some malware needs you to run it. A worm can spread on its own. It can move between vulnerable systems without needing a user to copy it manually. That is what makes worms dangerous. One infected system can become the starting point for many more.
000
William • SOC and Detection Engineering @williamincyber.bsky.social · 29/09/2026
The dangerous file may not look dangerous at all. That is the idea behind a Trojan. A Trojan disguises itself as legitimate software or a harmless file to trick someone into running it. The disguise earns the click. The malicious behavior comes after.
000
William • SOC and Detection Engineering @williamincyber.bsky.social · 29/09/2026
HOW A SOC INVESTIGATES AN ALERT ALERT ↓ VALIDATE ↓ ADD CONTEXT ↓ INVESTIGATE ↓ DECIDE ↓ RESPOND
000
William • SOC and Detection Engineering @williamincyber.bsky.social · 29/09/2026
Suspicious. Malicious. Unconfirmed. If you treat these as the same thing, you can reach the wrong verdict fast. Suspicious means investigate further. It does not automatically mean malicious.
100
William • SOC and Detection Engineering @williamincyber.bsky.social · 29/09/2026
Sometimes the easiest system to hack is a person. That is why social engineering works. Attackers manipulate trust, fear, urgency or curiosity to convince someone to reveal information or take an unsafe action. The target is not always the technology. Sometimes it is you.
000
William • SOC and Detection Engineering @williamincyber.bsky.social · 29/09/2026
The command worked. But if you had asked me WHY it worked, I couldn’t have explained it. That made me realize something: Getting the expected output from a cybersecurity lab doesn’t necessarily mean I understand what I just did.
100
William • SOC and Detection Engineering @williamincyber.bsky.social · 29/09/2026
One sentence is making me better at investigations: “I don’t have enough evidence yet.” When you’re learning SOC analysis, there’s a temptation to make every interesting finding mean something immediately.
100
William • SOC and Detection Engineering @williamincyber.bsky.social · 28/09/2026
Your password can be strong and still put another account at risk. How? Password reuse. Credential stuffing is when attackers take stolen credentials and try them on other services. One leaked password can unlock more than one account.
000
William • SOC and Detection Engineering @williamincyber.bsky.social · 28/09/2026
One password guess failing means little. Thousands against the same account tell a different story. That is brute force. An attacker repeatedly tries possible passwords until one works. For defenders, the pattern matters: Repeated failures can be the evidence.
000
William • SOC and Detection Engineering @williamincyber.bsky.social · 28/09/2026
One infected device is a problem. Thousands controlled together become something much bigger. That is a botnet. Attackers control networks of compromised devices to carry out activity such as DDoS attacks, spam or malware delivery. One controller. Many compromised devices.
000
William • SOC and Detection Engineering @williamincyber.bsky.social · 28/09/2026
The dangerous vulnerability might be the one defenders do not know about yet. That is a Zero Day. It is a vulnerability that is unknown to the party responsible for fixing it, leaving no official patch available yet. Unknown weakness. No fix yet. Real exposure.
000
William • SOC and Detection Engineering @williamincyber.bsky.social · 27/09/2026
“Just build a home lab” skips the hardest part. What do you actually investigate once it is running? I’ve learned to start with one question, generate the activity, then compare the logs I expected with what appeared. I’m turning that process into a series.
100
William • SOC and Detection Engineering @williamincyber.bsky.social · 27/09/2026
The SOC analyst role is changing. Knowing how to open an alert and follow a playbook is not enough. The path I’m building toward is deeper: SOC fundamentals Investigation Detection engineering Automation AI assisted SOC Agentic SOC
220
William • SOC and Detection Engineering @williamincyber.bsky.social · 27/09/2026
A security incident is only the beginning. What happens next matters. Incident Response is the structured process of identifying, containing, investigating and recovering from an incident. The goal is not just to stop the threat. It is to understand, contain and recover.
000
William • SOC and Detection Engineering @williamincyber.bsky.social · 27/09/2026
Want to learn networking for cybersecurity? I found this beginner course covering: Networking fundamentals LAN vs. WAN MAC addresses Routers and switches Client server networks Peer to peer networks Learn it. Build a lab. Practice it. Free resource: drive.google.com/drive/folder...
000
William • SOC and Detection Engineering @williamincyber.bsky.social · 27/09/2026
The attack may be over. The evidence it left behind can still tell a story. That is where IOCs matter. An Indicator of Compromise is evidence that may suggest malicious activity occurred. Think suspicious IPs, domains, hashes or files. The activity ends. The clues remain.
000
William • SOC and Detection Engineering @williamincyber.bsky.social · 26/09/2026
Being inside the network should not automatically make you trusted. That is the idea behind Zero Trust. Every access request should be evaluated based on identity, device, context and policy. Trust is not permanent. Access must be continuously verified.
000
William • SOC and Detection Engineering @williamincyber.bsky.social · 26/09/2026
A face behind the investigations. I’m building my path into SOC and detection engineering one lab at a time. Some days that means finding the answer. Other days it means documenting what I missed and testing again. I’m sharing both, because the process is part of the work.
000
William • SOC and Detection Engineering @williamincyber.bsky.social · 26/09/2026
Cybersecurity tools can generate thousands of signals. Someone still has to make sense of them. That is where a SOC comes in. A Security Operations Center monitors, investigates and responds to security threats. Tools generate signals. The SOC turns them into decisions.
000
William • SOC and Detection Engineering @williamincyber.bsky.social · 26/09/2026
Not every security tool is designed to stop the attack. Some are there to spot it. That is where an IDS comes in. An Intrusion Detection System monitors activity for suspicious behavior and generates alerts. Think of it as the alarm. It detects. You investigate.
000
William • SOC and Detection Engineering @williamincyber.bsky.social · 26/09/2026
What happens when thousands of devices hit the same service at once? It can become unavailable to real users. That is the goal of a DDoS attack. Attackers flood a target with traffic from many sources until its resources cannot handle the demand. Availability is the target.
000
William • SOC and Detection Engineering @williamincyber.bsky.social · 25/09/2026
Imagine opening your laptop and suddenly your own files are being held hostage. That is ransomware. It is malware designed to deny access to data or systems and demand payment. The scary part is not just encryption. Modern attacks may steal the data first.
000
William • SOC and Detection Engineering @williamincyber.bsky.social · 25/09/2026
Attackers do not always need to break security. Sometimes the weakness is already there. That weakness is a vulnerability. It could exist in software, configuration, or design and create an opportunity for exploitation. A vulnerability is the weakness. An exploit uses it.
000
William • SOC and Detection Engineering @williamincyber.bsky.social · 25/09/2026
SOC Home Lab Series | Part 28 Nmap gave me the result. The packet response helped me understand why. A SYN only shows that a connection was attempted. The response tells me what happened next.
100
William • SOC and Detection Engineering @williamincyber.bsky.social · 25/09/2026
A stolen password should not be enough to steal your account. That is the idea behind MFA. It requires more than one authentication factor before access is granted. Something you know. Something you have. Something you are. One password is no longer the whole defense.
000
William • SOC and Detection Engineering @williamincyber.bsky.social · 25/09/2026
Logging in proves who you are. It does not mean you can access everything. That is where authorization comes in. Authentication asks: Who are you? Authorization asks: What are you allowed to do? Similar words. Very different security decisions.
000